PT-2019-16738 · Gnome+7 · Gnome Shell+7

Doran Moppert

·

Published

2019-02-05

·

Updated

2024-10-03

·

CVE-2019-3820

CVSS v3.1

4.8

Medium

VectorAV:P/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions gnome-shell versions 3.15.91 and later
Description The gnome-shell lock screen does not properly restrict all contextual actions, allowing an attacker with physical access to a locked workstation to invoke certain keyboard shortcuts and potentially other actions.
Recommendations For gnome-shell versions 3.15.91 and later, consider disabling the lock screen feature until a patch is available to prevent potential exploitation. Restrict physical access to workstations to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:3553
ALT-PU-2019-1455
CESA-2019_3553
CESA-2020_1021
CVE-2019-3820
ELSA-2020-1021
OESA-2021-1403
OPENSUSE-SU-2019:1582-1
OPENSUSE-SU-2019_1529-1
OPENSUSE-SU-2019_1582-1
OPENSUSE-SU-2024:10797-1
RHSA-2019:3553
RHSA-2019_3553
RHSA-2020:1021
RHSA-2020_1021
RLSA-2019:3553
RLSA-2019_3553
SUSE-SU-2019:1390-1
SUSE-SU-2019:1459-1
SUSE-SU-2019_1390-1
SUSE-SU-2019_1459-1
USN-3966-1
USN-7052-1

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Gnome Shell